hmcts / roadmap-platform-operations

0 stars 0 forks source link

DARTs failover implementation (145) #2291

Open hmcts-platform-operations opened 2 weeks ago

hmcts-platform-operations commented 2 weeks ago

DTSPO-21958

Summary

DARTs flows are currently configured to flow a single firewall, Network Virtual Appliances (NVA). This limitation is currently known by the business and while some other solutions are being investigated long term, there is the probability that we'll have to deploy in production using same solution for traffic flows.

Definitions on the production rules and policies are currently in progress in DTSPO-19016.

We now need to think about the possibility that there is a scenario where the pinned Palo Alto firewall goes offline and how we can quickly failover to the second Palo Alto firewall as the default mechanism i.e. Loadbalancing is not at play for DARTs at the moment if current implementation is adopted in production.

Intended Outcome